GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,646
Maven
5,000+
npm
4,273
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
299 advisories
Filter by severity
Moodle has a CSRF risk in user tours manager that allows tour duplication
Low
CVE-2025-3635
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low
CVE-2024-45965
was published
for
contao/contao
(Composer)
Oct 2, 2024
•
withdrawn
concrete5 vulnerable to Cross-site Scripting
Low
CVE-2015-3989
was published
for
concrete5/concrete5
(Composer)
May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
Low
CVE-2014-6296
was published
for
jbartels/wec-map
(Composer)
May 17, 2022
Joomla! Cross-site Scripting vulnerability
Low
CVE-2013-5583
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5323
was published
for
sjbr/static-info-tables
(Composer)
May 17, 2022
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5100
was published
for
jambagecom/div2007
(Composer)
May 17, 2022
PHPUnit extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-4744
was published
for
oliverklee/phpunit
(Composer)
May 13, 2022
Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2012-5888
was published
for
b13/seo_basics
(Composer)
May 17, 2022
powermail extension for TYPO3 has Cross-site Scripting vulnerability
Low
CVE-2012-5889
was published
for
in2code/powermail
(Composer)
May 17, 2022
Moodle vulnerable to Cross-site Scripting
Low
CVE-2011-4282
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-Site Scripting
Low
CVE-2011-4299
was published
for
moodle/moodle
(Composer)
May 13, 2022
Symphony CMS vulnerable to Cross-site Scripting
Low
CVE-2011-4340
was published
for
symphonycms/symphony-2
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting vulnerability
Low
CVE-2011-4782
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Low
CVE-2011-4634
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Joomla! vulnerable to Cross-site Scripting
Low
CVE-2011-4332
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
MantisBT Cross-site Scripting vulnerability
Low
CVE-2010-2574
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
Commerce extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2009-4963
was published
for
commerceteam/commerce
(Composer)
May 2, 2022
Moodle doesn't properly check role
Low
CVE-2010-1617
was published
for
moodle/moodle
(Composer)
May 13, 2022
Piwik (now Matomo) Vulnerable to Cross-Site Scripting (XSS)
Low
CVE-2013-1844
was published
for
matomo/matomo
(Composer)
May 13, 2022
phpMyAdmin Vulnerable to Cross-Site Scripting
Low
CVE-2011-1940
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Moodle vulnerable to Cross-site Scripting
Low
CVE-2010-1619
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-site Scripting
Low
CVE-2010-1614
was published
for
moodle/moodle
(Composer)
May 13, 2022
SilverStripe vulnerable to Cross-site Scripting
Low
CVE-2010-1593
was published
for
silverstripe/cms
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API